CVE-2013-0270
Publication date 12 April 2013
Last updated 8 April 2026
Ubuntu priority
Cvss 3 Severity Score
Description
A flaw was found in OpenStack Keystone. A remote attacker could exploit this vulnerability by sending a large HTTP request, specifically by providing a long tenant name when requesting a token. This could lead to a denial of service, consuming excessive CPU and memory resources on the affected system.
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| keystone | ||
Notes
jdstrand
Keystone on 11.10 is a pre-release version and unusable with other components such as nova and horizon per upstream (and me), change is to intrusive for stable release update and the upstream patch was rejected for Folsom and earlier. This is more of a feature than a vulnerability.
Severity score breakdown
| Parameter | Value |
|---|---|
| Base score |
|
| Attack vector | Network |
| Attack complexity | Low |
| Privileges required | Low |
| User interaction | None |
| Scope | Unchanged |
| Confidentiality | None |
| Integrity impact | None |
| Availability impact | High |
| Vector | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |